使用YAML文件部署Kubernetes时遭遇STS角色权限错误
解决EKS中kubectl操作的sts:AssumeRole权限拒绝问题
问题现象
执行kubectl部署Kubernetes资源时,反复出现权限错误,所有集群操作(创建角色、集群角色绑定等)均失败:
部署Deployment时的错误
kubectl apply -f k8s/deployment.yml --validate=false An error occurred (AccessDenied) when calling the AssumeRole operation: User: <user arn> is not authorized to perform: sts:AssumeRole on resource: <cluster role arn> E1111 21:37:30.036257 14704 memcache.go:265] couldn't get current server API group list: Get "https://5E52EE866A68FF445D9EFF54FF06C3FF.gr7.ap-south-1.eks.amazonaws.com/api?timeout=32s": getting credentials: exec: executable aws failed with exit code 254 error: unable to recognize "k8s/deployment.yml": Get "https://5E52EE866A68FF445D9EFF54FF06C3FF.gr7.ap-south-1.eks.amazonaws.com/api?timeout=32s": getting credentials: exec: executable aws failed with exit code 254
部署ClusterRoleBinding时的错误
kubectl apply -f k8s/clusterrolebinding.yml --validate=false An error occurred (AccessDenied) when calling the AssumeRole operation: User: <<user arn>> is not authorized to perform: sts:AssumeRole on resource: <<cluster role arn>> E1112 12:33:01.210734 35556 memcache.go:265] couldn't get current server API group list: Get "https://5E52EE866A68FF445D9EFF54FF06C3FF.gr7.ap-south-1.eks.amazonaws.com/api?timeout=32s": getting credentials: exec: executable aws failed with exit code 254 error: unable to recognize "k8s/clusterrolebinding.yml": Get "https://5E52EE866A68FF445D9EFF54FF06C3FF.gr7.ap-south-1.eks.amazonaws.com/api?timeout=32s": getting credentials: exec: executable aws failed with exit code 254
解决方案
1. 检查目标IAM角色的信任策略
找到报错中<cluster role arn>对应的IAM角色,进入AWS控制台的IAM角色详情页,查看信任关系配置,确保当前用户的ARN(<user arn>)被允许扮演该角色:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "<user arn>" }, "Action": "sts:AssumeRole" } ] }
如果没有这条规则,添加后保存。
2. 检查当前用户的IAM权限
确保当前用户的IAM策略中包含允许sts:AssumeRole操作的权限,目标资源为上述集群角色ARN:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "sts:AssumeRole", "Resource": "<cluster role arn>" } ] }
如果用户没有相关权限,需要由管理员添加该策略。
3. 验证kubeconfig配置正确性
检查本地~/.kube/config文件中的用户配置片段,确认exec命令参数正确,特别是--role-arn字段是否指向正确的集群角色ARN:
users: - name: eks-cluster-user user: exec: apiVersion: client.authentication.k8s.io/v1beta1 command: aws args: - eks - get-token - --cluster-name - your-eks-cluster-name - --role-arn - <cluster role arn>
如果配置有误,修正后保存。
4. 手动测试角色切换
直接执行AWS CLI命令验证是否能成功获取临时凭证:
aws sts assume-role --role-arn <cluster role arn> --role-session-name test-kubectl-session
- 如果该命令报错,说明IAM权限问题未解决,回到步骤1和2排查;
- 如果命令成功返回临时凭证,再重新执行kubectl命令测试。
5. 验证EKS RBAC权限(角色切换成功后仍有问题)
如果成功获取凭证但kubectl操作仍失败,需要确认扮演的IAM角色对应的K8s RBAC权限是否足够:
- 确保该IAM角色已通过
ClusterRoleBinding或RoleBinding绑定到具有对应操作权限的K8s角色(比如cluster-admin或自定义角色)。
内容的提问来源于stack exchange,提问作者Srikar Marupaka
相关产品推荐
相关产品推荐

